SYS::ONLINE
Wasteland.
Briefs1481
Issues20
SinceFeb 2026
LIVE
⚡ Active KEV CVE-2026-60388 2026-07-21

CVE-2026-60388: Critical Unauthenticated Takeover in Oracle Service Delivery Platform

"A critical (CVSS 9.8) vulnerability in Oracle Fusion Middleware's Service Delivery Platform lets an unauthenticated attacker take over the product over the network via T3 or IIOP."

A critical (CVSS 9.8) vulnerability in Oracle Fusion Middleware's Service Delivery Platform lets an unauthenticated attacker take over the product over the network via T3 or IIOP.

What Is It

CVE-2026-60388 is a critical flaw in the Service Delivery Platform product of Oracle Fusion Middleware, specifically in the Messaging Enabler component. Per Oracle's advisory, the vulnerability is easily exploitable and allows an unauthenticated attacker with network access via the T3 or IIOP protocols to compromise the Service Delivery Platform. A successful attack can result in complete takeover of the product.

The issue carries a CVSS 3.1 base score of 9.8 (CRITICAL) with the vector AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H, reflecting network attack vector, low complexity, no privileges or user interaction required, and high impact to confidentiality, integrity, and availability.

Why It Matters

The combination of no authentication, low attack complexity, and full compromise makes this among the most severe class of vulnerabilities. Because exploitation occurs over T3 and IIOP, protocols commonly reachable in middleware deployments, an attacker with network access needs no credentials and no user interaction to seize control. The impact spans all three security pillars: data confidentiality, integrity, and system availability.

What's Vulnerable

The affected product is Oracle Service Delivery Platform (Oracle Fusion Middleware), component Messaging Enabler. The supported versions listed as affected are:

Patch Status

Oracle addressed this vulnerability in its July 2026 Critical Patch Update. Organizations running the affected versions should apply the fixes provided in the Oracle Critical Patch Update Advisory as their required remediation. No CISA KEV entry was supplied, so active exploitation is not confirmed by that source at this time.

Sources